CVE-2023-35147

CVSS v3.1 6.5 (Medium)
65% Progress
EPSS 0.12 % (46th)
0.12% Progress
Affected Products 1
Advisories 2

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not restrict the AWS SQS queue name path parameter in an HTTP endpoint, allowing attackers with Item/Read permission to obtain the contents of arbitrary files on the Jenkins controller file system.

Weaknesses
CWE-732
Incorrect Permission Assignment for Critical Resource
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2023-06-14 13:15:12
(15 months ago)
Updated Date
2023-06-23 15:30:53
(15 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Aws Codecommit Trigger for Jenkins 3.0.12 and prior versions cpe:2.3:a:jenkins:aws_codecommit_trigger::*:*:*:*:jenkins <= 3.0.12
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...